Comment by Calamityjanitor

1 day ago

This was always my pet peeve when working as a penetration tester. We'd run simple tools like this to cover the basics, but so many coworkers would blindly copy paste the issues without considering the site's context and suitability. Not to knock their skills, they'd find real vulnerabilities too. It's just that this stuff was considered beneath them, while I felt that giving a client tailored advice on little details like this is what they were looking for and shows attention to detail.

As a security conscious dev that has worked in various highly regulated spaces I want to say we really appreciate people like you, because they’re super rare